Microsoft patched the vulnerability in Office, CVE-2012-0158, more than a year ago although attackers are still frequently targeting it, including in the Safe and Taidoor campaigns, Leopando wrote.

If the email attachment is opened on an unpatched computer, a "backdoor" program is then installed that steals login credentials for websites and email credentials from Internet Explorer and Microsoft Outlook, Leopando wrote.

The stolen information was then sent to two IP addresses in Hong Kong, although those servers have since been shut down, he wrote.

The targets of the attack would suggest that hackers were looking for victims in the diplomatic community. Leopando noted that similar emails were also sent to some Chinese media organizations.

"The topic of the email -- and the attached document -- would be of interest to these targets," Leopando wrote. "In addition, the information stolen and where it was stolen from -- is very consistent with targeted attacks aimed at large organizations that use corporate mainstays like Internet Explorer and Outlook."

Copyright 2016 IDG Communications. ABN 14 001 592 650. All rights reserved. Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.